First published: Tue Nov 10 2009(Updated: )
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle VM VirtualBox | =2.0.10 | |
Oracle VM VirtualBox | =2.0.8 | |
Sun Virtual Desktop Infrastructure | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3923 is classified as a critical vulnerability due to its potential for unauthorized access without authentication.
To fix CVE-2009-3923, ensure that authentication is enabled for the web service in VirtualBox and Sun Virtual Desktop Infrastructure.
CVE-2009-3923 affects Oracle VM VirtualBox versions 2.0.8 and 2.0.10, as well as Sun Virtual Desktop Infrastructure version 3.0.
Yes, CVE-2009-3923 can be exploited remotely by attackers to gain unauthorized access.
A potential workaround for CVE-2009-3923 is to restrict access to the web service using firewall rules until a proper patch is applied.